Tool 13

When do the DPDP security safeguards become mandatory?

Check any DPDP obligation against Rule 1 of the Digital Personal Data Protection Rules, 2025 — whether it is in force today, the date it starts, and the sub-clause that commences it.

In short
The DPDP Rules, 2025 commence in three tranches under Rule 1. Rules 1, 2 and 17 to 21 took effect on publication, 13 November 2025. Rule 4, Consent Manager registration, follows on 13 November 2026. Everything a Data Fiduciary must do — notice, security safeguards, breach intimation, retention, Data Principal rights and transfers abroad — commences on 13 May 2027.

What this obligation turns on

Rule 6 is the obligation where "not in force" is least useful as a planning answer. The seven minimum safeguards it names — encryption or tokenisation, access control, monitoring able to detect unauthorised access, backups, a year of logs, contractual terms binding processors, and measures ensuring all of it is observed rather than adopted — are a programme rather than a policy. The eighteen months Rule 1(4) allows are the build time, and an organisation treating the date as distant is measuring from the wrong end.

QuestionAnswer
In force today?No
Binds from13 May 2027
Imposed byRule 6Reasonable security safeguards
Commenced byRule 1(4), “eighteen months after the date of publication of this Gazette
Commencement of maintaining reasonable security safeguards under the DPDP Rules, 2025.

Rule 6 names seven minimum safeguards: encryption, obfuscation, masking or tokenisation; access control; logs and monitoring sufficient to detect unauthorised access; backups for continued processing; one year of log and data retention; security provisions in Data Processor contracts; and measures ensuring the safeguards are observed rather than merely adopted.

Check another obligation

The same resolution for every other duty in the Rules — the rule that imposes it, the sub-clause that commences it, and whether it binds today.

The obligation you are asking about

Every obligation is resolved to the rule that imposes it, and every rule to the sub-clause of Rule 1 that commences it. Dates are computed from publication on 13 November 2025.

Not yet13 May 2027

Maintaining reasonable security safeguards is imposed by rule 6, Reasonable security safeguards. Rule 1(4) commences it “eighteen months after the date of publication of this Gazette”, which is 13 May 2027, so it does not bind today and nothing under it is yet enforceable.

Rule 6 names seven minimum safeguards: encryption, obfuscation, masking or tokenisation; access control; logs and monitoring sufficient to detect unauthorised access; backups for continued processing; one year of log and data retention; security provisions in Data Processor contracts; and measures ensuring the safeguards are observed rather than merely adopted.

Commencement under Rule 1 of the DPDP Rules, 2025
Sub-clauseFromRulesWhat it covers
Rule 1(2)13 November 20251, 2 and 17 to 21the definitions, and the machinery of the Data Protection Board — its appointment, its terms of service, and its functioning as a digital office
Rule 1(3)13 November 20264the registration and obligations of Consent Managers, and nothing else
Rule 1(4)Yours13 May 20273, 5 to 16, 22 and 23everything a Data Fiduciary has to do — notice, security safeguards, breach intimation, retention limits, Data Principal rights, Significant Data Fiduciary obligations and transfers outside India

Indicative, and not legal advice. Rule 1 of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025. Whether a given obligation reaches your organisation is a determination for your legal team.

Take this away as a print-ready commencement schedule

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

The full commencement picture sets out all three tranches and why the notification date decides every one of them.

Rule 1 of the Digital Personal Data Protection Rules, 2025, read from MeitY’s own gazette PDF ofG.S.R. 846(E). Indicative, and not legal advice.

Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

Does the DPDP 72-hour breach notification rule apply now?
No. Rule 7 of the Digital Personal Data Protection Rules, 2025 requires a full report to the Data Protection Board within seventy-two hours of becoming aware of a personal data breach, but Rule 1(4) commences rule 7 eighteen months after publication — 13 May 2027. Until then there is no DPDP breach-reporting duty of any length. The six-hour report to CERT-In is a separate obligation under section 70B of the IT Act 2000 and has been in force since June 2022.
Is the DPDP Act in force in India?
Partly. The Digital Personal Data Protection Act, 2023 and the Rules of 2025 are both notified, but commencement is phased. As at today the provisions in force are the definitions and the machinery of the Data Protection Board — its appointment, terms of service and functioning as a digital office. No obligation on a Data Fiduciary is in force until 13 May 2027, other than Consent Manager registration, which starts on 13 November 2026.
When do DPDP penalties start?
A penalty attaches to breaching an obligation, so it can only follow that obligation into force. The Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration on 13 November 2026, and every Data Fiduciary duty on 13 May 2027. Claims that the penalty framework "applies from day one" describe a Board that exists but has no Data Fiduciary duty to adjudicate until the third tranche commences.
When must we register as a Consent Manager?
Rule 4 commences on 13 November 2026, one year after publication, and it is the only rule in that tranche. An organisation that is not offering Consent Manager services has no obligation on that date at all — the next date that reaches an ordinary Data Fiduciary is 13 May 2027.
Were the DPDP Rules notified on 13 or 14 November 2025?
The 13th. G.S.R. 846(E) is dated 13 November 2025; the 14th appears only in the e-gazette upload stamp CG-DL-E-14112025-267650 printed on the cover page. The distinction is load-bearing because Rule 1 sets commencement as an interval from publication rather than as fixed dates, so taking the 14th moves every downstream date by a day and makes "notified 14 November" and "in force 13 May 2027" mutually inconsistent.
What DPDP obligations are in force today?
Seven rules: rules 1 and 2, which are the short title and the definitions, and rules 17 to 21, which appoint the Chairperson and Members of the Data Protection Board, set their terms of service, govern the Board’s meetings and let it function as a digital office. All seven concern the regulator rather than the regulated. No safeguard, notice, retention or breach duty is among them.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools